Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS0zd3g3LTQ2Y2gtN3JxMs4AAtH0
AES OCB fails to encrypt some bytes
AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimized implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was pre-existing in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed.
Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected.
Permalink: https://github.com/advisories/GHSA-3wx7-46ch-7rq2JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zd3g3LTQ2Y2gtN3JxMs4AAtH0
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 2 years ago
Updated: about 1 year ago
CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Identifiers: GHSA-3wx7-46ch-7rq2, CVE-2022-2097
References:
- https://nvd.nist.gov/vuln/detail/CVE-2022-2097
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=919925673d6c9cfed3c1085497f5dfbbed5fc431
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=a98f339ddd7e8f487d6e0088d4a9a42324885a93
- https://rustsec.org/advisories/RUSTSEC-2022-0032.html
- https://www.openssl.org/news/secadv/20220705.txt
- https://lists.fedoraproject.org/archives/list/[email protected]/message/V6567JERRHHJW2GNGJGKDRNHR7SNPZK7/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/R6CK57NBQFTPUMXAPJURCGXUYT76NQAK/
- https://security.netapp.com/advisory/ntap-20220715-0011/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA/
- https://security.gentoo.org/glsa/202210-02
- https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf
- https://www.debian.org/security/2023/dsa-5343
- https://lists.debian.org/debian-lts-announce/2023/02/msg00019.html
- https://security.netapp.com/advisory/ntap-20230420-0008/
- https://github.com/advisories/GHSA-3wx7-46ch-7rq2
Affected Packages
cargo:openssl-src
Dependent packages: 9Dependent repositories: 3,600
Downloads: 18,993,906 total
Affected Version Ranges: < 111.22.0, >= 300.0.0, < 300.0.9
Fixed in: 111.22.0, 300.0.9
All affected versions: 110.0.0, 110.0.0, 110.0.1, 110.0.2, 110.0.3, 110.0.4, 110.0.5, 110.0.6, 110.0.7, 111.0.0, 111.0.1, 111.1.0, 111.1.1, 111.2.1, 111.3.0, 111.4.0, 111.5.0, 111.6.0, 111.6.1, 111.7.0, 111.8.0, 111.8.1, 111.9.0, 111.10.0, 111.10.1, 111.10.2, 111.11.0, 111.12.0, 111.13.0, 111.14.0, 111.15.0, 111.16.0, 111.17.0, 111.18.0, 111.19.0, 111.20.0, 111.21.0, 300.0.0, 300.0.1, 300.0.2, 300.0.3, 300.0.4, 300.0.5, 300.0.6, 300.0.7, 300.0.8
All unaffected versions: 111.22.0, 111.23.0, 111.24.0, 111.25.0, 111.25.1, 111.25.2, 111.25.3, 111.26.0, 111.27.0, 111.28.0, 111.28.1, 300.0.9, 300.0.10, 300.0.11, 300.0.12, 300.0.13, 300.1.0, 300.1.1, 300.1.2, 300.1.3, 300.1.4, 300.1.5, 300.1.6, 300.2.0, 300.2.1, 300.2.2, 300.2.3